Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A developer wants to ensure that a container runs as a non-root user and the filesystem is read-only except for a tmpfs volume. Which fields should be set in the container's securityContext?

⚠ Common exam trap

CNCF often tests the distinction between `runAsUser` (which sets a UID but does not enforce non-root) and `runAsNonRoot` (which enforces non-root but does not set a UID), leading candidates to pick Option A when they only need to ensure non-root, not a specific UID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsNonRoot: true and readOnlyRootFilesystem: true

`runAsNonRoot: true` enforces that the container cannot run as the root user (UID 0), and `readOnlyRootFilesystem: true` makes the container's filesystem read-only except for volumes explicitly mounted as writable, such as a tmpfs volume. Together, these fields satisfy the requirement of a non-root container with a read-only filesystem except for a tmpfs mount.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    runAsUser: 1000 and readOnlyRootFilesystem: true

    Why it's wrong here

    runAsUser: 1000 explicitly sets the container process UID to 1000, but it does not act as a validation gate: Kubernetes will not refuse to run an image that attempts to execute as root, and a later misconfiguration could change the UID to 0. readOnlyRootFilesystem: true only makes the filesystem read-only; it has no effect on which user runs the process. The requirement asks for a guarantee that the container runs as non-root, which is exactly what the runAsNonRoot: true flag enforces by rejecting root UIDs at pod creation.

  • ✗

    runAsNonRoot: true and privileged: false

    Why it's wrong here

    runAsNonRoot: true ensures the container process does not run as UID 0, which satisfies the non-root requirement, but privileged: false is only the default absence of privileged mode—it does not mount the root filesystem as read-only and does not prevent writes to container layers. A non-root process can still modify its writable filesystem, so the read-only condition is left unmet. Without readOnlyRootFilesystem: true, the container retains write access to its root filesystem, violating the stated goal.

  • ✓

    runAsNonRoot: true and readOnlyRootFilesystem: true

    Why this is correct

    runAsNonRoot: true instructs Kubernetes to verify that the container's user ID is non-zero before starting, and it rejects the pod if the image would run as root or if no non-root user is specified. readOnlyRootFilesystem: true forces the container's root filesystem to be mounted read-only, so even a compromised non-root process cannot write to system directories. Together these two settings directly address both requirements: a non-root process with a read-only root filesystem.

  • ✗

    allowPrivilegeEscalation: false and readOnlyRootFilesystem: true

    Why it's wrong here

    allowPrivilegeEscalation: false stops a process from gaining extra privileges through setuid binaries or other privilege-raising mechanisms, but it leaves the container free to run with a root UID, which is the exact condition the developer wants to prevent. readOnlyRootFilesystem: true does protect the root filesystem, but the container could still be running as root, which means the non-root criterion is not guaranteed. The combination lacks runAsNonRoot: true or an equivalent user constraint.

About these practice questions

Courseiva writes every CKAD question from scratch — 826 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.